[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2e43qty5sf17x":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":15,"seoTitleEn":28,"seoDescription":15,"seoDescriptionEn":29,"logoUrl":30,"isVerified":31,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda48825201","GFAN","GFAN Alleged Data Exposure","gfan","gfan.com","2016-10-10T00:00:00.000Z","2016-10-10T16:32:34.000Z","2026-07-29T11:13:00.741Z","Third party breach","",[],22526334,"known",null,"records","Critical",[23,24,25,26],"Reported email addresses","Reported IP addresses","Reported usernames","Reported salted or hashed passwords","\u003Cp>\u003Cstrong>The October 2016 dataset attributed to GFAN is unverified.\u003C\u002Fstrong> public breach source catalogues 22,526,334 accounts with emails, IPs, usernames, and salted or hashed passwords but expressly says that while portions appear legitimate, attribution to GFAN could not be conclusively established. October 10 is both the structured and catalogue-added date, not a proven attack day.\u003C\u002Fp>\u003Cp>The local job processed emails only from five pipe-delimited chunks. It reports 22,477,285 valid or processed lines and 22,427,206 imported emails; public breach source's external measure is respectively 49,049 and 99,128 higher. With source and normalized files and backup missing, the 50,079 processing-to-import gap, duplicates, nulls, rejected values, and corpus version cannot be re-audited.\u003C\u002Fp>\u003Cp>A private result establishes only that the controlled email occurs in the local email subset attributed to GFAN. It cannot establish identity, a GFAN account or community, Chinese-service use, IP or location, username or password, field co-occurrence, password recovery or reuse, compromise, or misuse.\u003C\u002Fp>\u003Cp>No specific cracking claim should be made until password algorithm and prevalence are authenticated. Users should never enter an old password into a search form; only an authenticated password reused elsewhere should be replaced. Uncertain account attribution, IPs, and credential associations must remain private.\u003C\u002Fp>","GFAN Alleged Data Exposure (22.5 Million Records)","GFAN Alleged Data Exposure. 22.5 Million records were reported. Reported data: Reported email addresses, Reported ip addresses, Reported usernames. Review the…","\u002Fuploads\u002Flogo\u002Fgfan_com.webp",false,{"name":7,"sector":33,"country":34,"website":10,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Mobile Technology Forum","China"]